CVE-2026-17176EPSS p92.0%
CVE-2026-17176CVE-2026-17176
Description
An OS
command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an
adjacent network attacker to execute arbitrary commands with root privileges by
sending a crafted UDP packet.
Successful exploitation may lead to complete
device compromise, including unauthorized command execution, modification of
device settings, and loss of confidentiality, integrity, and availability
Scoring
| EPSS | 4.97% probability of exploitation · percentile 92.0% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-01 |